Security Researcher Discloses New Batch of MySQL Vulnerabilities

The first MySQL vulnerability, a stack-based buffer overflow, would allow an authenticated database user a chance to cause the MySQL daemon to crash, and then execute code with the same privileges as the user running MySQL. A heap-based overflow vulnerability, separate from the previous flaw, could be used to do the same thing – again the damage could be caused by an authenticated database user.

via Security Researcher Discloses New Batch of MySQL Vulnerabilities | SecurityWeek.Com.

Windows XP Drops Below 40% Market Share, Windows 8 Passes 1%

While the 1 percent share for Windows 8 is completely expected, it’s interesting to note that less than half of users have chosen to stick with the default IE10 browser: just 0.51 percent. Everyone else appears to be using Chrome, Firefox, or yet another browser.

via Windows XP Drops Below 40% Market Share, Windows 8 Passes 1%.

Happy bday! SMS txt msgs turn 20

The approval was finally given and the systems interconnected, then Papworth, sitting in front of a personal computer, tapped out the greeting “Merry Christmas” and sent it via SMS to Vodafone Director Richard Jarvis.

The text-messaging era was born.

via Happy bday! SMS txt msgs turn 20 – Computerworld.

Perhaps it’s no surprise then that in late 1995, three years after Papworth’s first text message, users were only sending an average of one text every two and a half months.

Theresa Christy of Otis Elevator: Making Elevators Go

Here is a typical problem: A passenger on the sixth floor wants to descend. The closest car is on the seventh floor, but it already has three riders and has made two stops. Is it the right choice to make that car stop again? That would be the best result for the sixth-floor passenger, but it would make the other people’s rides longer.

via Theresa Christy of Otis Elevator: Making Elevators Go | Creating – WSJ.com.

Dig pcap File For Fun and Productivity

To solve the problem I used Perl (feel free to use your favorite language) to open a pcap file and do some analysis. Let us look at finding sessions where the client sent data but the server didn’t send any data in response. To make it easy I’ve included all the steps I took and, where appropriate, the code. Since the point is to illustrate how to use script language like Perl to do the job, the code is greatly simplified. For the convenience of reader, the complete code is listed at the end.

Via Dig pcap File For Fun and Productivity | BreakingPoint.

Extracting Data from Network Captures pcap with Perl

When I am analyzing network activity generated by malware, I am most interested in HTTP get/posts, the addresses the malware is communicating with, and the data that was actually sent or received.

via Extracting Data from Network Captures pcap with Perl « Mick’s Mix.

Chaosreader is a Perl script that takes a pcap file as its argument and will create communication summaries in a report format. It will also pull data from the tcp streams (within the pcap) and re-assemble the actual files.

A Light Bulb with a Computer and Projector Inside from the MIT Media Lab Augments Reality

The LuminAR device, created by Linder and colleagues at the Media Lab, can project interactive images onto a surface, sensing when a person’s finger or hand points to an element within those images. Linder describes LuminAR as an augmented-reality system because the images and interfaces it projects can alter the function of a surface or object. While LuminAR might seem like a far-fetched concept, many large technology companies are experimenting with new kinds of computer interfaces in hopes of discovering new markets for their products (see “Google Game Could Be Augmented Reality’s First Killer App” and ”A New Chip to Bring 3-D Gesture Control to Smartphones”).

via A Light Bulb with a Computer and Projector Inside from the MIT Media Lab Augments Reality | MIT Technology Review.

Mars Science Laboratory: Update Set In San Francisco About Curiosity Mars Rover

Rumors and speculation that there are major new findings from the mission at this early stage are incorrect. The news conference will be an update about first use of the rover’s full array of analytical instruments to investigate a drift of sandy soil. One class of substances Curiosity is checking for is organic compounds — carbon-containing chemicals that can be ingredients for life. At this point in the mission, the instruments on the rover have not detected any definitive evidence of Martian organics.

via Mars Science Laboratory: Update Set In San Francisco About Curiosity Mars Rover.

Probably in reference to this site:

Mars Exploration Rover Mission: Press Releases.

It had me going for awhile and it’s not even April 1.  People like having fun on these intertubes.  🙂

Optical SDN Gets a Test Run

Building an OTS boils down to adding two things to an optical transport box: a virtual switch and the software hooks to receive commands from OpenFlow or some similar protocol. Infinera outfitted its gear accordingly, and ESnet provided a home-built SDN controller to talk to it.

via Optical SDN Gets a Test Run – Optical Networking – Telecom News Analysis – Light Reading.

The OTS used in the tests is nowhere near commercial viability, both sides tell Light Reading. The software doesn’t have operational niceties such as alarms or debugging tools, for instance.

OTS=Optical Transport Switch

Are Your Facebook Friends Stressing You Out? (Yes)

Facebook’s power, and its curse, is this holistic treatment of personhood. All the careful tailoring we do to ourselves (and to our selves) — to be, say, professional in one context and whimsical in the other — dissolves in the simmering singularity of the Facebook timeline. The circumstantially mediated relationships typical of IRL interactions — you see your boss at work, your friend after work, your mother-in-law at Thanksgiving — are mediated instead by one overarching, and overpowering, circumstance: Facebook.

via Are Your Facebook Friends Stressing You Out? (Yes) – Megan Garber – The Atlantic.